Educause Security Discussion mailing list archives

Re: Question About Password Resets


From: Roger A Safian <r-safian () NORTHWESTERN EDU>
Date: Thu, 16 May 2013 16:12:10 +0000

We have security questions and answers set when the accounts are created.  I'm not a fan of them myself, but, I 
recognize their usefulness in situations like this.  If those fail, the user would need to contact a department chair, 
program coordinator, etc. and have that person contact our help desk in order to authorize the change.

From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Jim 
Pardonek
Sent: Thursday, May 16, 2013 11:00 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] Question About Password Resets

We've recently had some issues with our current password reset process, particularly when a faculty or staff member is 
out of town and calls for a password reset.  We also have an issue because our campuses are spread out geographically 
which makes it difficult for someone to come in person.  I apologize if this has been discussed before, but I was 
wondering what other institutions are doing regarding password resets via telephone?  Or do you do something else.  I 
am looking to make a recommendation to "re-tool" our password reset policy and process so any input would be most 
welcome.

Thanks,

Jim


James Pardonek, CISSP, CEH
Information Security Officer
Loyola University Chicago
1032 W. Sheridan Road | Chicago, IL  60660

*: (773) 508-6086

Current thread: